CVE-2021-25487

CVE Published 2021-10-06
Related CWE(s) CWE-125: Out-of-bounds Read
Related Vendor(s) google
Related Product(s) android
Exploitation Reported (CISA KEV) 2023-06-29
CVSS 3 Base Score 7.3 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References